CVE-2016-9563: SAP NetWeaver XML External Entity (XXE) Vulnerability
Medium severity, CVSS 6.5. Actively exploited: in CISA KEV since 2021-11-03. EPSS: 24.2% chance of exploitation in the next 30 days.
BC-BMT-BPM-DSK in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to conduct XML External Entity (XXE) attacks via the sap.com~tc~bpem~him~uwlconn~provider~web/bpemuwlconn URI, aka SAP Security Note 2296909.
Affected products
- SAP NetWeaver Application Server Java: version 7.50 only
Published 2016-11-23. Last modified 2026-06-17.